Virus

Bonjour,
mon ordinateur rame énormément et des fenêtres intempestives s'ouvre sans arret quand je me connecte à internet. merci de maider sachant que je suis débutante.
Configuration: Windows XP
Internet Explorer 7.0

6 réponses

  1. Modérateur
    Salut,

    - Télécharge HijackThis Version 2.02 :
    = = = = >>> En cliquant ici <<< = = = =

    - Enregistre HJTInstall.exe sur ton bureau.
    - Fais un double-clic (gauche) sur HJTInstall.exe afin de lancer l’installation
    - Clique sur Install ensuite sur « I Accept »
    - Clique sur « Do a scan system and save log file »
    - Le bloc-notes s’ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
    0
    1. bonsoir,
      Télécharges hijackthis
      http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis
      .Cliques sur "télécharger hijackthis"
      .enregistres le sur le bureau
      .Renommes hijackthis en tutu.exe
      .Tu fermes tout les programmes ouverts y compris le navigateur. sauf ton anti-virus et pare-feux
      .installes le , il va s'installer par défaut dans C:\Program Files\Trend Micro\HijackThis
      .Cliques sur "Do a system scan and save the logfile"
      .Cela va t'ouvrir un bloc note à la fin du scan.
      .Copie son contenu et poste le dans ton prochain message. sinon le rapport est dans C:\Program Files\Trend Micro\HijackThis\ hijackthis "document texte"

      si besion d'aide pour l'installation : https://www.malekal.com/tutoriel-hijackthis/

      et si problème pour VISTA :https://www.sosordi.net/

      des expliquations en images pour l'utiliser : http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm

      Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement
      0
      1. voici le rapport hijackthis :

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 00:49:07, on 21/04/2009
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16827)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
        C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
        C:\WINDOWS\system32\atwtusb.exe
        C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Hp\digital imaging\bin\hpqtra08.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\HPQ\SHARED\HPQWMI.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        c:\documents and settings\jojo\local settings\application data\koeqe.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Windows Live\Toolbar\wltuser.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Windows Live\Contacts\wlcomm.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/...
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.openoffice.org/welcome/registration20.html
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
        O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
        O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
        O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
        O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
        O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
        O4 - HKLM\..\Run: [EPSON Stylus D88 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABE.EXE /P23 "EPSON Stylus D88 Series" /O6 "USB002" /M "Stylus D88"
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [koeqe] "c:\documents and settings\jojo\local settings\application data\koeqe.exe" koeqe
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - S-1-5-18 Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe (User 'SYSTEM')
        O4 - .DEFAULT Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe (User 'Default user')
        O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\digital imaging\bin\hpqtra08.exe
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/...
        O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.mypix.com/importer/ImageUploader4.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{C7012880-A6BA-42A7-B6A8-44A241C06DF8}: NameServer = 212.27.40.240,212.27.40.241
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        0
        1. Modérateur
          Nettoyage avec Navilog1:

          * Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
          * Relance Navilog par double clic sur le raccourci Navilog présent sur ton bureau
          * Au menu principal, choisis 2 et valide.
          * Il va t’informer qu’il va alors redémarrer ton PC
          * Appuie sur une touche comme demandé (Si ton PC ne redémarre pas automatiquement, fais le toi même)
          * Au redémarrage de ton PC, choisis ta session habituelle.

          * Patiente jusqu’au message :
          *** Nettoyage Termine le ..... ***

          * Le bloc note va s’ouvrir, copie/colle ici le rapport, comme tu l’as fait pour l’autre.
          0
          1. je n'ai pas navilog1sur mon bureau, comment faire? faut-il le télécharger?
            0
        2. Modérateur
          Excuse moi, je t'ai pas donné le bon texte !
          Oublie ça pour le moment !
          Fais ceci :

          Tu as une infection Navipromo / Magic control.
          Télécharge sur le bureau Navilog1 (Merci à IL-MAFIOSO)
          = = = = >>> En cliquant ici <<< = = = =
          * La console noire de Navilog1 doit s’ouvrir après l’installation
          * Sinon, pour l’ouvrir, double-clique sur le raccourci « Navilog1 » sur ton bureau
          * Appuie sur la lettre F de ton clavier puis sur la touche Entrée
          * Appuie sur une touche de ton clavier pour continuer...
          * Tape 1, puis appuie sur la touche Entrée de ton clavier
          * Ainsi, Navilog1 va effectuer la recherche des fichiers infectieux sur ton PC.
          * NE PAS UTILISER L’OPTION 2, 3, 4 SANS AVIS
          * Sois patient, cela peut prendre une dizaine de minutes
          * Navilog1 t’informe que la recherche est terminée
          * Appuie sur une touche de ton clavier pour afficher le rapport qu’il a généré
          * Le rapport sera sauvegardé dans le fichier suivant : « fixnavi.txt » à la racine de ton disque dur (C:\fixnavi.txt).
          * Poste le rapport généré
          0
          1. voici le rapport navilog1 :

            Search Navipromo version 3.7.6 commencé le 21/04/2009 à 1:48:28,75

            !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
            !!! Postez ce rapport sur le forum pour le faire analyser !!!
            !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

            Outil exécuté depuis C:\Program Files\navilog1

            Mise à jour le 14.03.2009 à 18h00 par IL-MAFIOSO

            Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
            X86-based PC ( Uniprocessor Free : Mobile AMD Sempron(tm) Processor 3000+ )
            BIOS : Phoenix NoteBIOS 4.0 Release 6.1
            USER : jojo ( Administrator )
            BOOT : Normal boot

            Antivirus : avast! antivirus 4.8.1335 [VPS 090419-0] 4.8.1335 (Activated)

            C:\ (Local Disk) - NTFS - Total:55 Go (Free:7 Go)
            D:\ (CD or DVD)

            Recherche executé en mode normal

            *** Recherche dossiers dans "C:\WINDOWS" ***

            *** Recherche dossiers dans "C:\Program Files" ***

            *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

            *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

            *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

            *** Recherche dossiers dans "C:\Documents and Settings\jojo\applic~1" ***

            *** Recherche dossiers dans "C:\Documents and Settings\jojo\locals~1\applic~1" ***

            *** Recherche dossiers dans "C:\Documents and Settings\jojo\menudm~1\progra~1" ***

            *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
            pour + d'infos : http://www.gmer.net

            *** Recherche avec GenericNaviSearch ***
            !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
            !!! A vérifier impérativement avant toute suppression manuelle !!!

            * Recherche dans "C:\WINDOWS\system32" *

            * Recherche dans "C:\Documents and Settings\jojo\locals~1\applic~1" *

            *** Recherche fichiers ***

            *** Recherche clés spécifiques dans le Registre ***
            !! Les clés trouvées ne sont pas forcément infectées !!

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "koeqe"="\"c:\\documents and settings\\jojo\\local settings\\application data\\koeqe.exe\" koeqe"

            *** Module de Recherche complémentaire ***
            (Recherche fichiers spécifiques)

            1)Recherche nouveaux fichiers Instant Access :

            2)Recherche Heuristique :

            * Dans "C:\WINDOWS\system32" :

            * Dans "C:\Documents and Settings\jojo\locals~1\applic~1" :

            koeqe.exe trouvé !
            koeqe.dat trouvé !
            koeqe_nav.dat trouvé !
            koeqe_navps.dat trouvé !

            3)Recherche Certificats :

            Certificat Egroup absent !
            Certificat Electronic-Group absent !
            Certificat Montorgueil absent !
            Certificat OOO-Favorit absent !
            Certificat Sunny-Day-Design-Ltd absent !

            4)Recherche autres dossiers et fichiers connus :

            *** Analyse terminée le 21/04/2009 à 2:03:16,54 ***
            0